# Hariharan M
Cyber Threat Intelligence Researcher

- Email: hariharan.mathankumar@gmail.com
- Phone: +91 9566714246
- Portfolio: https://misterxcrypt.github.io/
- LinkedIn: https://linkedin.com/in/hariharanmathan
- GitHub: https://github.com/misterxcrypt
- Medium: https://medium.com/@misterxcrypt

## Summary
Cyber Threat Intelligence Researcher with 3+ years across attack surface management, digital
risk protection, brand protection, dark web research and cybercrime investigation. Built the collection and correlation systems behind
156,413 UPI IDs mapped to 598 fraud websites, structured for referral to I4C and NPCI. Skilled in OSINT, HUMINT and
dark web tradecraft, from sock-puppet operations to on-chain cryptocurrency
tracing, with team-wide SOPs authored for persona management and
brand-impersonation investigation.

## Experience

### Cyber Threat Intelligence Researcher, Redhunt Labs
May 2025 to July 2026 | Remote
- Built internet-scale reconnaissance on AWS and Terraform using ZMap and zgrab2, indexing exposed-asset results in Elasticsearch.
- Led Digital Risk Protection investigations for enterprise clients: phishing campaigns, brand impersonation, rogue applications, exposed infrastructure, dark web threats.
- Ran technical proofs of concept during customer evaluations across ASM, dark web and ransomware monitoring and brand protection, partnering with pre-sales.
- Engineered phishing monitoring from Certificate Transparency logs, typosquatting analysis and domain intelligence, enriched via VirusTotal and URLScan.io.
- Designed a Telegram intelligence platform monitoring hundreds of channels and groups.
- Authored team SOPs for persona management and brand-impersonation investigation, standardising OPSEC practice across the CTI team.
- Conducted AI security research into asset discovery, exposure monitoring, fingerprinting and secret-leakage detection.
- Redesigned ASM reporting into separate executive and technical tracks; contributed to the DRP product roadmap.

### Cyber Threat Intelligence Analyst, Saptang Labs
January 2023 to May 2025 | IIT MRP, India
- Built the money mule and scam intelligence system: 156,413 UPI IDs mapped to 598 fraud websites, structured for referral to I4C and NPCI, 2,000+ malicious advertising domains, 1,000+ phishing sites; real-time threat identification up 75%.
- Led OSINT, HUMINT and social engineering investigations across crypto scams, lottery and gambling schemes and mule networks.
- Monitored 20+ underground forums, marketplaces and Telegram channels, mapping TTPs to MITRE ATT&CK; produced 80+ intelligence reports.
- Detected phishing sites, cloned APKs and impersonation campaigns including 2,000+ SEO-poisoned .gov.in pages and 10,000+ fraudulent bank customer-care numbers on YouTube.
- Conducted threat actor engagements under OPSEC procedure to verify data leaks and establish modus operandi.
- Supported law enforcement and regulatory investigations into financial fraud, terrorist funding and extremist networks.

## Independent research
Unaffiliated with any employer, conducted on personal time.
- Dark web research and on-chain analysis: tracked carding platforms, cloned-card marketplaces and child-exploitation infrastructure; clustered sites by hosting and template similarity for operator attribution; traced cryptocurrency flows.
- Hacktivist and disinformation network tracking: profiled coordinated collectives and cross-platform propaganda infrastructure during regional conflict.
- Cybercrime complaint platform: WhatsApp-based intake and case tracking for a local cybercrime response unit, cutting manual handling by an estimated 75%.

## Projects
- **Cryptic Grove** (TypeScript, SCSS, Docker) public cyber security knowledge base, 11 stars. https://github.com/misterxcrypt/cryptic-grove
- **Telescribe** (Python, FastAPI, React/TypeScript) OSINT relationship map between Telegram channels; AI-classifies messages and surfaces IOCs. https://github.com/misterxcrypt/telescribe
- **ReconEye** (Python, Selenium, Celery, MongoDB, Docker) external attack surface management with distributed collection workers. https://github.com/misterxcrypt/Recon-Engine
- **Forums Bank** (OSINT) curated repository of cybercrime forums, marketplaces and leak sites; contributor. https://forums-bank.vercel.app/

## Skills
- **Intelligence**: Cyber Threat Intelligence, OSINT, HUMINT, Digital Risk Protection, Dark Web Intelligence, Attack Surface Management, MITRE ATT&CK, Brand Protection
- **Tradecraft**: Sock-puppet operations, cybercrime ecosystem mapping, infrastructure attribution, crypto on-chain analysis, Certificate Transparency monitoring
- **Engineering**: Python, FastAPI, Flask, React/TypeScript, AWS, Terraform, ZMap, zgrab2, Elasticsearch, MongoDB, Celery, Selenium, Docker
- **Tooling**: Shodan, Censys, VirusTotal, URLScan.io, SecurityTrails, FOFA, Maltego, Google dorking, Burp Suite, Wireshark

## Education
**B.Tech, Computer Science and Business Systems**
Sri Eshwar College of Engineering, 2021 to 2025 | CGPA 8.61
Organised cybersecurity seminars, workshops and CTF events; competed with team NandBytes.

## Certifications
- ArcX Foundation Threat Intelligence Analyst, December 2024
- Kase Scenarios, Betrayal OSINT Training
- Tracelabs OSINT Coach
- (ISC)² Certified in Cybersecurity
- Cisco Introduction to Cyber Security

## Recognition
- Co-authored the Payment Gateway Security Handbook
- Smart Hack Challenge winner, 2022
- Rajya Puraskar Award, 2019
- Published security research on Medium: OSINT investigations, HackTheBox write-ups, CVEs

## Unconfirmed
Two figures appear on earlier versions of this CV but are not corroborated by the
underlying evidence inventory, and are withheld pending confirmation:
a ~90% first-hop mule account closure rate, and a sub-28-hour global IPv4 HTTPS sweep.
